{"api_version":"1","generated_at":"2026-08-27T21:18:48+00:00","cve":"CVE-2026-64279","urls":{"html":"https://cve.report/CVE-2026-64279","api":"https://cve.report/api/cve/CVE-2026-64279.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-64279","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-64279"},"summary":{"title":"i2c: core: fix adapter deregistration race","description":"In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: core: fix adapter deregistration race\n\nAdapters can be looked up by their id using i2c_get_adapter() which\ntakes a reference to the embedded struct device.\n\nRemove the adapter from the IDR before tearing it down during\nderegistration (and on registration failure) to make sure its resources\nare not accessed after having been freed (e.g. the device name).","state":"PUBLISHED","assigner":"Linux","published_at":"2026-07-25 10:17:08","updated_at":"2026-08-17 05:17:27"},"problem_types":["CWE-362"],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/d39282f552dd6c35b9b84b4af78f1198c24f3373","name":"https://git.kernel.org/stable/c/d39282f552dd6c35b9b84b4af78f1198c24f3373","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/bb234487a447a99315add1b46aa57b72e163e1eb","name":"https://git.kernel.org/stable/c/bb234487a447a99315add1b46aa57b72e163e1eb","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/35dbd1f1f603401155cbd3a180bb18e3a3b675b8","name":"https://git.kernel.org/stable/c/35dbd1f1f603401155cbd3a180bb18e3a3b675b8","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/11dfa37bf544cc806f21742ca2fd2d841bd7032e","name":"https://git.kernel.org/stable/c/11dfa37bf544cc806f21742ca2fd2d841bd7032e","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/b1a58ed9eab146b36f41a55db8f5d7ce9fdedf3f","name":"https://git.kernel.org/stable/c/b1a58ed9eab146b36f41a55db8f5d7ce9fdedf3f","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/b6d2af6fe9c1f5ec0484536753c979cbd40a8ac3","name":"https://git.kernel.org/stable/c/b6d2af6fe9c1f5ec0484536753c979cbd40a8ac3","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/9882a9bd74db08e7bae5821a7050627ae92d3380","name":"https://git.kernel.org/stable/c/9882a9bd74db08e7bae5821a7050627ae92d3380","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-64279","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64279","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 35fc37f8188177e3ba3e7f99a6e3300e490e9181 d39282f552dd6c35b9b84b4af78f1198c24f3373 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 35fc37f8188177e3ba3e7f99a6e3300e490e9181 11dfa37bf544cc806f21742ca2fd2d841bd7032e git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 35fc37f8188177e3ba3e7f99a6e3300e490e9181 9882a9bd74db08e7bae5821a7050627ae92d3380 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 35fc37f8188177e3ba3e7f99a6e3300e490e9181 bb234487a447a99315add1b46aa57b72e163e1eb git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 35fc37f8188177e3ba3e7f99a6e3300e490e9181 b6d2af6fe9c1f5ec0484536753c979cbd40a8ac3 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 35fc37f8188177e3ba3e7f99a6e3300e490e9181 35dbd1f1f603401155cbd3a180bb18e3a3b675b8 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 35fc37f8188177e3ba3e7f99a6e3300e490e9181 b1a58ed9eab146b36f41a55db8f5d7ce9fdedf3f git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2.6.31","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 2.6.31 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.212 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.178 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.145 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.96 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.39 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.4 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2026","cve_id":"64279","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"64279","cve":"CVE-2026-64279","epss":"0.001640000","percentile":"0.060520000","score_date":"2026-08-03","updated_at":"2026-08-04 00:07:35"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/i2c/i2c-core-base.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"d39282f552dd6c35b9b84b4af78f1198c24f3373","status":"affected","version":"35fc37f8188177e3ba3e7f99a6e3300e490e9181","versionType":"git"},{"lessThan":"11dfa37bf544cc806f21742ca2fd2d841bd7032e","status":"affected","version":"35fc37f8188177e3ba3e7f99a6e3300e490e9181","versionType":"git"},{"lessThan":"9882a9bd74db08e7bae5821a7050627ae92d3380","status":"affected","version":"35fc37f8188177e3ba3e7f99a6e3300e490e9181","versionType":"git"},{"lessThan":"bb234487a447a99315add1b46aa57b72e163e1eb","status":"affected","version":"35fc37f8188177e3ba3e7f99a6e3300e490e9181","versionType":"git"},{"lessThan":"b6d2af6fe9c1f5ec0484536753c979cbd40a8ac3","status":"affected","version":"35fc37f8188177e3ba3e7f99a6e3300e490e9181","versionType":"git"},{"lessThan":"35dbd1f1f603401155cbd3a180bb18e3a3b675b8","status":"affected","version":"35fc37f8188177e3ba3e7f99a6e3300e490e9181","versionType":"git"},{"lessThan":"b1a58ed9eab146b36f41a55db8f5d7ce9fdedf3f","status":"affected","version":"35fc37f8188177e3ba3e7f99a6e3300e490e9181","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/i2c/i2c-core-base.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"2.6.31"},{"lessThan":"2.6.31","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.212","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.178","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.145","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.96","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.39","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.4","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.212","versionStartIncluding":"2.6.31","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.178","versionStartIncluding":"2.6.31","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.145","versionStartIncluding":"2.6.31","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.96","versionStartIncluding":"2.6.31","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.39","versionStartIncluding":"2.6.31","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.4","versionStartIncluding":"2.6.31","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"2.6.31","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: core: fix adapter deregistration race\n\nAdapters can be looked up by their id using i2c_get_adapter() which\ntakes a reference to the embedded struct device.\n\nRemove the adapter from the IDR before tearing it down during\nderegistration (and on registration failure) to make sure its resources\nare not accessed after having been freed (e.g. the device name)."}],"metrics":[{"cvssV3_1":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - An attacker reaches the vulnerable lookup through local open/openat calls on /dev/i2c-N and can trigger dynamic-adapter teardown through local usbfs ioctls. No network path directly reaches i2c_get_adapter().\nAC:L - An attacker with access to both device nodes can control both sides by racing parallel I2C opens against repeatable USBDEVFS_DISCONNECT and rebind operations. No victim-controlled timing or uncontrollable condition is required.\nPR:L - i2cdev_open() and the usbfs disconnect path impose device-node DAC, LSM, and device-cgroup checks but no capability requirement. A regular user granted I2C and USB-device access can trigger the race without init-namespace root.\nUI:N - The attacker can initiate the adapter lookup, software disconnect, and subsequent stale-adapter operations directly. No separate victim action is required.\nS:U - Exploitation corrupts or executes code within the same host kernel security authority. This is ordinary local kernel privilege escalation rather than a VM, IOMMU, or other scope-boundary escape.\nC:H - The race can return an adapter after its embedded device resources have been released, followed by freeing of the enclosing dynamic-adapter allocation. Reclaiming this heap object permits attacker-influenced pointer dereferences and potential arbitrary kernel-memory disclosure.\nI:H - The stale adapter contains algorithm and locking function pointers, while I2C ioctls also write mutable adapter fields. Heap reclamation can therefore provide memory-corruption and control-flow-hijacking primitives leading to kernel code execution.\nA:H - Refcount resurrection, stale device-resource accesses, and dereferences through a freed adapter can produce kernel warnings, oopses, or panics. An attacker controlling disconnect and rebind can repeat the trigger."}]}],"providerMetadata":{"dateUpdated":"2026-08-17T04:52:34.328Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/d39282f552dd6c35b9b84b4af78f1198c24f3373"},{"url":"https://git.kernel.org/stable/c/11dfa37bf544cc806f21742ca2fd2d841bd7032e"},{"url":"https://git.kernel.org/stable/c/9882a9bd74db08e7bae5821a7050627ae92d3380"},{"url":"https://git.kernel.org/stable/c/bb234487a447a99315add1b46aa57b72e163e1eb"},{"url":"https://git.kernel.org/stable/c/b6d2af6fe9c1f5ec0484536753c979cbd40a8ac3"},{"url":"https://git.kernel.org/stable/c/35dbd1f1f603401155cbd3a180bb18e3a3b675b8"},{"url":"https://git.kernel.org/stable/c/b1a58ed9eab146b36f41a55db8f5d7ce9fdedf3f"}],"title":"i2c: core: fix adapter deregistration race","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-64279","datePublished":"2026-07-25T08:49:23.145Z","dateReserved":"2026-07-19T15:36:31.777Z","dateUpdated":"2026-08-17T04:52:34.328Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-25 10:17:08","lastModifiedDate":"2026-08-17 05:17:27","problem_types":["CWE-362"],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.31","versionEndExcluding":"5.15.212","matchCriteriaId":"FE528008-C559-4313-A979-99A5D04AE74B"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.16","versionEndExcluding":"6.1.178","matchCriteriaId":"092233C7-F4E0-40C8-BD4D-A28FE50DFE20"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2","versionEndExcluding":"6.6.145","matchCriteriaId":"7046B092-F810-4440-ACE6-60218518EECE"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7","versionEndExcluding":"6.12.96","matchCriteriaId":"38A8100E-2B1A-462F-AEE9-8901B870FEF2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.13","versionEndExcluding":"6.18.39","matchCriteriaId":"914AE4BC-3D59-4C5A-9DB5-9CE327B429F7"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.19","versionEndExcluding":"7.1.4","matchCriteriaId":"6228DDD6-4557-4AA3-9F43-AB995D471E42"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"64279","Ordinal":"1","Title":"i2c: core: fix adapter deregistration race","CVE":"CVE-2026-64279","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"64279","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: core: fix adapter deregistration race\n\nAdapters can be looked up by their id using i2c_get_adapter() which\ntakes a reference to the embedded struct device.\n\nRemove the adapter from the IDR before tearing it down during\nderegistration (and on registration failure) to make sure its resources\nare not accessed after having been freed (e.g. the device name).","Type":"Description","Title":"i2c: core: fix adapter deregistration race"}]}}}